Privacy Policy

Last updated: September 2026

Overview

DataStruct AI ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our document intelligence platform.

Information We Collect

Account Information: Email address, full name, organisation name, and password (hashed using bcrypt).

Document Content: Documents you upload are stored in Cloudflare R2 object storage, which encrypts stored data at rest as a property of the platform, and their extracted text is held in our managed PostgreSQL database. Documents are scoped to one workspace and are never shared across organisations.

Usage Data: Audit logs of actions taken in the platform (uploads, searches, rule executions) for security and compliance purposes.

Technical Data: IP address, browser type, device information collected through standard server logs.

How We Use Your Information

  • Provide and maintain the DataStruct AI service
  • Process documents through extraction and AI analysis pipelines
  • Notify you of platform activity and product updates (with your consent)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations and respond to lawful requests

Data Security

We implement industry-standard security measures including:

  • HTTPS (TLS) for data in transit
  • Encryption at rest for stored files and the database, provided by the hosting platforms (Cloudflare R2, Railway)
  • Workspace-level data isolation enforced in the application layer on every request (membership and permission checks); there is no per-tenant database
  • Role-based access control (RBAC) with granular permission types
  • Audit logging of sensitive write actions (uploads, deletions, review decisions, administrative changes); read access by platform administrators is not currently logged
  • Internal security reviews before each release; no third-party penetration test has been performed yet

AI Processing

Documents are processed in our managed cloud and by third-party AI providers (OpenAI) for extraction, summarisation, and Q&A. We do not allow these providers to use your data for training. When a document is ingested, chunks of its extracted text are sent to the AI provider to create search embeddings and an extract is sent for claim detection; when you ask a question or run a requirement, your question and the retrieved passages are sent to generate and check the answer. Whole files are never sent. Our error monitoring (Sentry, EU region) receives error reports with request paths and identifiers; request bodies are stripped before they are sent.

Your Rights

Under GDPR, CCPA, and similar regulations, you have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your account (profile, memberships and API keys); documents you uploaded remain in their workspace, unlinked from you, until purged on request
  • Export your data in machine-readable format
  • Object to processing for marketing purposes

Data export and account deletion are available from your account settings (Security tab). Where deletion cannot be completed self-serve — for example if you are the sole owner of an organisation — email hello@datastructai.com and we complete it for you. For other requests, contact privacy@datastructai.com.

Data Retention

Account data is retained while your account is active. Deleting your account removes your profile, memberships and API keys. Deleting a document hides it immediately from search, questions, lists and evidence packs; the stored file and derived data are permanently removed when we run a purge, which we do on request — contact us to purge a document, a pilot workspace or an account. No automatic retention job runs during the private beta. Database backups can hold a copy of deleted data until they are rotated, within 30 days.

Cookies & Analytics

We use essential cookies for authentication and session management. These are required for the service to function.

Optional analytics cookies (PostHog) are loaded only when you click "Accept all" in our cookie banner. They collect anonymised usage data (pages visited, features used) so we can improve the product. We do not use cookies for advertising, retargeting, or selling data to third parties.

You can change your cookie preferences at any time by clearing your browser's site data for this domain. The consent banner will reappear.

Sub-processors

We use the following third-party processors to deliver the service:

ProcessorPurposeLocation
RailwayHosting: application, PostgreSQL database, RedisUS
OpenAIAI inference (no training on your data)US
Cloudflare R2Object storage for uploaded files and exports (encrypted at rest by the platform)US (single region)
PostHogProduct analytics (anonymised; loaded only with your consent)US
SentryError monitoring (error reports without request bodies)EU
Resend (SMTP)Transactional emails (welcome, password reset, invitations)US/EU

We will give 30 days notice via email or product banner before adding or replacing any sub-processor that handles your personal data.

Marketing Communications & Lead Capture

When you submit your email through our free tools (Contract Analyser, Policy Summariser, ESG Disclosure Checker), we store it to send occasional product updates. The lawful basis is your consent at the point of submission.

You can unsubscribe at any time using the link in any marketing email, or by contacting privacy@datastructai.com. We do not share your email with third parties for marketing purposes.

Contact Us

For privacy-related questions, contact us at privacy@datastructai.com. We have not appointed a Data Protection Officer.